TL;DR
An exploit on multiple fronts shook the DeFi ecosystem, with two attacks that caused losses exceeding $31 million in a matter of hours. AFX Trade, a decentralized exchange for perpetual contracts on Arbitrum that settles in USDC, was drained and lost $24.15 million after an attacker compromised the custody bridge operated by the protocol itself. Blockchain security firm Blockaid confirmed the incident. AFX noted that the exact attack vector remains under investigation.
The on-chain trail documented by PeckShield reveals that the attacker converted the stolen USDC into 12,468 ETH, assets that were concentrated in a single wallet. AFX suspended bridge operations immediately and clarified that the vulnerability was “isolated to the custody bridge operated by AFX” and could not affect the protocol’s trading infrastructure or the Arbitrum network. Steven Goldfeder, co-founder of Arbitrum, was quick to publicly clarify that the network’s native bridge “was not hacked or exploited in any way.”
#PeckShieldAlert @AFX_XYZ on #Arbitrum has been exploited for ~$24M USDC. The exploiter has bridged the stolen funds from #Abitrum to #Ethereum and swapped them for 12,467.5 $ETH, currently sitting in 0x6276…ebAC.https://t.co/INZ7ZxtRhE pic.twitter.com/fUHFfEn1F5
— PeckShieldAlert (@PeckShieldAlert) July 23, 2026
Hours after the incident, Ken C, AFX’s head of growth, published a direct offer to the attacker: return 70% of the funds and keep the remaining 30% as a “white hat” bounty. The tactic is not new in the crypto industry; Drift Protocol on Solana attempted a similar negotiation after losing $285 million in an exploit in April.

The second attack of the day targeted the Verus-Ethereum bridge, which lost approximately $7.54 million through the same class of vulnerability exploited in May. According to Blockaid, the attacker abused the bridge’s import path to generate unbacked payments on the Ethereum side, draining ETH, tBTC, USDC, USDT, EURC, MKR, and scrvUSD before converting everything into ETH. CertiK estimated losses at $7.53 million and confirmed that the funds were deposited into Tornado Cash.
#PeckShieldAlert @BSquaredNetwork on #BNBChain has been drained of 8.591M $B2 (worth ~$3.86M).
The exploiter swapped the stolen funds for over 5K $WBNB, then swapped them to 1,128 $ETH and bridged out via NEAR Intents. $B2 has dropped -15%. pic.twitter.com/S7qWobFLJ9
— PeckShieldAlert (@PeckShieldAlert) July 23, 2026
What deepens the gravity of the case is that this second attack used the same contract, the same entry path, and the same class of vulnerability as the May exploit, though with a different attacker operating from a new wallet. The previous incident had caused losses of $11.6 million, though the attacker returned 4,052 ETH after retaining 25% as a bounty.
Is today Hackers' Day?
Three exploits have already happened today, with total losses of $35.55M.
AFX Trade(@AFX_XYZ) was exploited for $24.15M.
Verus(@VerusCoin) Ethereum bridge was exploited for $7.55M.
B² Network(@BSquaredNetwork) was exploited for $3.86M. pic.twitter.com/9v1KxWtaHV
— Lookonchain (@lookonchain) July 23, 2026
Finally, less than an hour later, PeckShield reported that attackers drained 8.59 million B2 tokens from BSquaredNetwork on BNB Chain, resulting in losses of approximately $3.86 million. The hackers quickly swapped the tokens for more than 5,000 WBNB, then converted them into 1,128 ETH before bridging the funds out via NEAR Intents
Both attacks add to the list of a devastating year for decentralized finance, which has accumulated more than $840 million in losses from hacks during 2026.